Cyber threats and risks are increasing exponentially with time. For preventing and defense against these threats and risks, precise risk perception for effective mitigation is the first step. Risk perception is necessary requirement to mitigate risk as it drives the security strategy at the organizational level and human attitude at individual level. Sometime, individuals understand there is a risk that a negative event or incident can occur, but they do not believe there will be a personal impact if the risk comes to realization but instead, they believe that the negative event will impact others. This belief supports the common belief that individuals tend to think of themselves as invulnerable, i.e. , optimistically bias about the situation, thus affecting their attitude for taking preventive measures due to inappropriate risk perception or overconfidence. The main motivation of this me ta-analysis is to assess that how the cyber optimistic bias or cyber optimism bias affects individual’s cyber security risk perception and how it changes their decisions. Applying a meta-analysis, this study found that optimistic bias has an overall negative impact on the cyber security due to the inappropriate risk perception and considering themselves invulnerable by biasing that the threat will not occur to them. Due to the cyber optimism bias, the individual will sometimes share passwords by considering it will not be maliciously used, lack in adopting of preventive measures, ignore security incidents, wrong perception of cyber threats and overconfidence on themselves in the context of cyber security.
Tsagourias, N. and Farrell, M. (2020). Cyber Attribution: Technical and Legal Approaches and Challenges. European Journal of International Law, 31, 941-967. https://doi.org/10.1093/ejil/chaa057
Rundle, J. (2022, October 5) Rise in Cyberattacks Stretches and Stresses Defenders. Wall Street Journal. https://www.wsj.com/articles/rise-in-cyberattacks-stretches-and-stresses-defenders-11664962202
Sayegh, E. (2022, December 15) Top Cybersecurity Predictions 2023. Forbes. https://www.forbes.com/sites/emilsayegh/2022/12/15/top-cybersecurity-predictions-2023
Hughes-Lartey, K., Li, M., Botchey, F.E. and Qin, Z. (2021) Human Factor, a Critical Weak Point in the Information Security of an Organization’s Internet of Things. Heliyon, 7, e06522. https://doi.org/10.1016/j.heliyon.2021.e06522
Morgan, S. (2022, December 12) Top 10 Cybersecurity Predictions and Statistics for 2023. Cybercrime Magazine. https://cybersecurityventures.com/stats
Morgan, S. (2021, January 21) 2021 Report: Cyberwarfare in the C-Suite—Cybercrime Facts and Statistics. Cybercrime Magazine. https://cybersecurityventures.com/wp-content/uploads/2021/01/Cyberwarfare-2021-Report.pdf
Rahman, T., Rohan, R., Pal, D. and Kanthamanon, P. (2021) Human Factors in Cybersecurity: A Scoping Review. The 12th International Conference on Advances in Information Technology, Bangkok, June 2021, Article No. 5. https://doi.org/10.1145/3468784.3468789
Hadlington, L. (2021) The “Human Factor” in Cybersecurity: Exploring the Accidental Insider. In: Research Anthology on Artificial Intelligence Applications in Security, IGI Global, Hershey, 1960-1977. https://doi.org/10.4018/978-1-7998-7705-9.ch087
Hadlington, L. (2017) Human Factors in Cybersecurity; Examining the Link between Internet Addiction, Impulsivity, Attitudes towards Cybersecurity, and Risky Cybersecurity Behaviours. Heliyon, 3, e00346. https://doi.org/10.1016/j.heliyon.2017.e00346
Ray, S. (2022, September 20) Social Engineering: How a Teen Hacker Allegedly Managed to Breach both Uber and Rockstar Games. Forbes. https://www.forbes.com/sites/siladityaray/2022/09/20/social-engineering-how-a-teen-hacker-allegedly-managed-to-breach-both-uber-and-rockstar-games
Weinstein, N.D. (1980) Unrealistic Optimism about Future Life Events. Journal of Personality and Social Psychology, 39, 806-820. https://doi.org/10.1037/0022-3514.39.5.806
Pfleeger, S.L. and Caputo, D.D. (2012) Leveraging Behavioral Science to Mitigate Cyber Security Risk. Computers & Security, 31, 597-611. https://doi.org/10.1016/j.cose.2011.12.010
Chapin, J.R. and Pierce, M. (2012) Optimistic Bias, Sexual Assault, and Fear. The Journal of General Psychology, 139, 19-28. https://doi.org/10.1080/00221309.2011.635724
Komatsu, A., Takagi, D. and Takemura, T. (2013) Human Aspects of Information Security. Information Management & Computer Security, 21, 5-15. https://doi.org/10.1108/09685221311314383
Gratian, M., Bandi, S., Cukier, M., Dykstra, J. and Ginther, A. (2018) Correlating Human Traits and Cyber Security Behavior Intentions. Computers & Security, 73, 345-358. https://doi.org/10.1016/j.cose.2017.11.015
Schwarzer, R. (1994) Optimism, Vulnerability, and Self-Beliefs as Health-Related Cognitions: A Systematic Overview. Psychology & Health, 9, 161-180. https://doi.org/10.1080/08870449408407475
Weinstein, N.D. and Klein, W.M. (1996) Unrealistic Optimism: Present and Future. Journal of Social and Clinical Psychology, 15, 1-8. https://doi.org/10.1521/jscp.1996.15.1.1
Jalali, M.S., Siegel, M. and Madnick, S. (2019) Decision-Making and Biases in Cybersecurity Capability Development: Evidence from a Simulation Game Experiment. The Journal of Strategic Information Systems, 28, 66-82. https://doi.org/10.1016/j.jsis.2018.09.003
Cunningham, M. (2020) Thinking about Thinking: Exploring Bias in Cybersecurity with Insights from Cognitive Science. https://www.forcepoint.com/sites/default/files/resources/files/report_thinking_about_thinking_cybersecurity_bias_en.pdf
Parsons, K., Mccormac, A., Butavicius, M. and Ferguson, L. (2010) Human Factors and Information Security: Individual, Culture and Security Environment. https://apps.dtic.mil/sti/pdfs/ADA535944.pdf
Rhee, H.-S., Ryu, Y.U. and Kim, C.-T. (2012) Unrealistic Optimism on Information Security Management. Computers & Security, 31, 221-232. https://doi.org/10.1016/j.cose.2011.12.001
Wiederhold, B.K. (2014) The Role of Psychology in Enhancing Cybersecurity. Cyberpsychology, Behavior, and Social Networking, 17, 131-132. https://doi.org/10.1089/cyber.2014.1502
Ross, R. (2022, January 1) More Assurance, Less Seat of the Pants. https://www.linkedin.com/pulse/new-years-resolution-more-assurance-less-seat-pants-ron-ross
Rhee, H.-S., Ryu, Y.U. and Kim, C.-T. (2005) I Am Fine but You Are Not: Optimistic Bias and Illusion of Control on Information Security. International Conference on Information Systems, Las Vegas, 11-14 December 2005, 11-24.
Hewitt, B. and White, G.L. (2020) Optimistic Bias and Exposure Affect Security Incidents on Home Computer. Journal of Computer Information Systems, 62, 50-60. https://doi.org/10.1080/08874417.2019.1697860
Hewitt, B. and White, G. (2021) Factors Influencing Security Incidents on Personal Computing Devices. Journal of Organizational and End User Computing, 33, 185-208. https://doi.org/10.4018/JOEUC.20210701.oa9
Lei, W., Hu, S. and Hsu, C. (2022) Unveiling the Process of Phishing Precautions Taking: The Moderating Role of Optimism Bias. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4147323
Chen, H. and Yuan, Y. (2022) The Impact of Ignorance and Bias on Information Security Protection Motivation: A Case of e-Waste Handling. Internet Research. https://doi.org/10.1108/INTR-04-2022-0238
Picincu, A. (2018) Role of Information Systems in an Organization. Bizfluent. https://bizfluent.com/about-6525978-role-information-systems-organization.html
Nosova, E., Anisimova, L., Murovana, T., Sviatiuk, Y. and Iafinovych, O. (2021) Information Security System in Provision of the Economic Security and Risk Management of the Enterprise. https://ceur-ws.org/Vol-3188/paper3.pdf
Stewart, L.A., Clarke, M., Rovers, M., Riley, R.D., Simmonds, M., Stewart, G. and Tierney, J.F. (2015) Preferred Reporting Items for a Systematic Review and Meta-analysis of Individual Participant Data. JAMA, 313, 1657. https://doi.org/10.1001/jama.2015.3656
White, G., Ekin, T. and Visinescu, L. (2016) Analysis of Protective Behavior and Security Incidents for Home Computers. Journal of Computer Information Systems, 57, 353-363. https://doi.org/10.1080/08874417.2016.1232991
Whitty, M., Doodson, J., Creese, S. and Hodges, D. (2015) Individual Differences in Cyber Security Behaviors: An Examination of Who Is Sharing Passwords. Cyberpsychology, Behavior, and Social Networking, 18, 3-7. https://doi.org/10.1089/cyber.2014.0179
Marek, J.M. (2015) Presence of Optimistic Bias and Illusion of Control in Information Security Risk Perceptions. https://www.proquest.com/openview/488e1f743c01c2f6bdfdf4d6c839154d/1?pq-origsite=gscholar&cbl=18750
Williams, A., et al. (2019) Employee Behavioural Factors and Information Security Standard Compliance in Nigeria Banks. International Journal of Computing and Digital Systems, 8, 387-396. https://doi.org/10.12785/ijcds/080407
Ament, C. (2017) The Ubiquitous Security Expert: Overconfidence in Information Security. Semantic Scholar.
Chung, S. (2010) Optimistic Bias about Online Privacy Risks: Testing the Moderating Effects of Perceived Controllability and Prior Experience. Computers in Human Behavior, 26, 987-995. https://doi.org/10.1016/j.chb.2010.02.012
Hak, T., van Rhee, H. and Suurmond, R. (2016) How to Interpret Results of Meta-Analysis. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.3241367
Wilson, D. B. (2019) Practical Meta-Analysis Effect Size Calculator. https://www.campbellcollaboration.org/escalc/html/EffectSizeCalculator-Home.php
Borenstein, M., Hedges, L.V., Higgins, J.P. and Rothstein, H.R. (2010) A Basic Introduction to Fixed-Effect and Random-Effects Models for Meta-Analysis. Research Synthesis Methods, 1, 97-111. https://doi.org/10.1002/jrsm.12
Borenstein, M., Hedges, L.V., Higgins, J.P.T. and Rothstein, H.R. (2021) Introduction to Meta-Analysis. Second Edition, Wiley, Hoboken. https://doi.org/10.1002/9781119558378
Hedges, L.V. and Vevea, J.L. (1998) Fixed and Random-Effects Models in Meta-Analysis. Psychological Methods, 3, 486-504. https://doi.org/10.1037/1082-989X.3.4.486
Borenstein, M., Hedges, L.E., Higgins, J.P.T. and Rothstein, H.R. (2022) Comprehensive Meta-Analysis Version 4. Biostat, Inc., Tampa. https://www.Meta-Analysis.com
Borenstein, M., Higgins, J.P., Hedges, L.V. and Rothstein, H.R. (2017) Basics of Meta-Analysis: I2 Is Not an Absolute Measure of Heterogeneity. Research Synthesis Methods, 8, 5-18. https://doi.org/10.1002/jrsm.1230
Higgins, J.P.T. and Thomas, J. (2019) Cochrane Handbook for Systematic Reviews of Interventions. 2nd Edition, Wiley, Hoboken. https://doi.org/10.1002/9781119536604
IntHout, J., Ioannidis, J.P.A., Rovers, M.M. and Goeman, J.J. (2016) Plea for Routinely Presenting Prediction Intervals in Meta-Analysis. BMJ Open, 6, e010247. https://doi.org/10.1136/bmjopen-2015-010247